CVE-2026-0233 is a certificate validation vulnerability affecting Palo Alto Networks Autonomous Digital Experience Manager on Windows systems. An unauthenticated attacker with adjacent network access can exploit this flaw to execute arbitrary code with NT AUTHORITY\SYSTEM privileges, granting them complete system control. The vulnerability requires only adjacent network proximity to exploit and does not demand prior authentication, representing a moderately accessible attack vector. However, the CVSS score is not currently available, though the FAUCET Risk Score of 32.0/100 suggests moderate risk concern. There is no evidence of active exploitation in the wild, as the vulnerability is not included on the KEV catalog and remains inactive on threat intelligence hot lists. The EPSS score of 0.00013 indicates minimal current exploitation probability relative to other disclosed vulnerabilities, suggesting limited immediate threat to organizations at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.10.0, < 5.10.14CPE matchmatch criteria | cpe:2.3:a:paloaltonetworks:autonomous_digital_experience_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Green
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.